2026-09-08 (TUESDAY): XWORM INFECTION
NOTICE:
- Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.
ASSOCIATED FILES:
- 2026-09-08-XWorm-notes.txt.zip 0.9 kB (9,38 bytes)
- 2026-09-08-XWorm-post-infection-traffic.pcap.zip 4.9 kB (4,853 bytes)
- 2026-09-08-XWorm-files.zip 452.9 kB (452,931 bytes)
2026-09-08 (TUESDAY): XWORM INFECTION EMAIL INFORMATION: - Return-Path: amedrano.tornillo@gmail[.]com - Received: from gmail[.]com (unknown [217.60.195[.]100]) by [information removed]; Tue, 08 Sep 2026 17:43:14 +0000 (UTC) - From: Alejandra Medrano (amedrano.tornillo@gmail[.]com) - To: [information removed] - Subject: ENVIO DOCUMENTOS FACTURA 4558 - Date: 08 Sep 2026 10:43:13 -0700 ATTACHED FILE: - SHA-256 hash: 9b4e654a8435d91c7f4e24e7fd844cbbb62328131b0065bc5a534c6e948c02c5 - File size: 141,703 bytes - File type: RAR archive data, v5 - File name: PAGO-ENVIO DOCUMENTOS FACTURA 4558.LZH EXTRACTED MALWARE FOR XWORM: - SHA-256 hash: 5ba1eee1204710adfe1963b730de79c7a8089b173e811052e7be464fc5da1a1d - File size: 207,267 bytes - File type: ASCII text, with very long lines, with CRLF, LF line terminators - File name: PAGO-ENVIO DOCUMENTOS FACTURA 4558.js - Sandbox analysis: https://www.joesandbox.com/analysis/1970315 - Sandbox analysis: https://tria.ge/260908-ymwaaagp3s/ - Sandbox analysis: https://app.any.run/tasks/7654b48a-cf1a-41f7-a65e-73d82381401c XWORM C2 TRAFFIC: - tcp[:]//43.228.157[.]141:7007/ NOTES: - The infection did not survive a reboot on my infected Windows host.
Click here to return to the main page.
